Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Kaseya Virtual System Administrator | 17/2/2020 | 17/6/2026 | Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2)… | |
| Modificada | Media (5.5) | 0.74% | — | Lenovo Xclarity Administrator | 14/2/2020 | 17/6/2026 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure. | |
| Modificada | Alta (7.5) | 1.0% | — | Lenovo Xclarity Administrator | 14/2/2020 | 17/6/2026 | An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes. | |
| Modificada | Media (5.4) | 0.52% | — | Lenovo Xclarity Administrator | 14/2/2020 | 17/6/2026 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code… | |
| Modificada | Alta (8.8) | 14% | 💥 Exploit | Kaseya Virtual System Administrator | 13/2/2020 | 17/6/2026 | Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx. | |
| Modificada | Alta (7.5) | 2.2% | — | Minisnmpd Project Minisnmpd | 4/2/2020 | 17/6/2026 | A stack buffer overflow vulnerability exists in the way MiniSNMPD version 1.4 handles multiple connections. A specially timed sequence of SNMP connections can trigger a stack overflow, resulting in a denial of service. To trigger this vulnerability, an attacker needs to simply initiate multiple connections to the… | |
| Modificada | Alta (8.2) | 2.6% | — | Minisnmpd Project Minisnmpd | 4/2/2020 | 17/6/2026 | An exploitable out of bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out of bounds memory read which can result in sensitive information disclosure and Denial Of Service. In order to trigger this vulnerability, an attacker… | |
| Modificada | Crítica (9.1) | 2.4% | — | Minisnmpd Project Minisnmpd | 4/2/2020 | 17/6/2026 | An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To trigger this vulnerability, an attacker… | |
| Modificada | Alta (7.5) | 3.1% | — | Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+20 | 21/1/2020 | 17/6/2026 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. | |
| Modificada | Media (5.3) | 2.4% | — | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications BRM - Elastic Charging EngineOracle Communications Diameter Signaling Router+23 | 17/1/2020 | 17/6/2026 | Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and… | |
| Modificada | Alta (7.5) | 89% | 💥 PoC | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+29 | 17/1/2020 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. | |
| Modificada | Crítica (9.8) | 2.0% | — | InfinispanRedhat Jboss Data Grid | 2/1/2020 | 17/6/2026 | A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling. | |
| Modificada | Alta (7.5) | 5.6% | — | Xmlsoft Libxml2Debian LinuxOracle Real User Experience InsightFedoraproject Fedora+8 | 24/12/2019 | 17/6/2026 | xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. | |
| Modificada | Alta (7.8) | 0.37% | — | Administrative Tools FOR Intel Network Adapters | 16/12/2019 | 17/6/2026 | Insufficient memory protection in the Linux Administrative Tools for Intel(R) Network Adapters before version 24.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 5.4% | — | SqliteSiemens Sinec Infrastructure Network ServicesTenable.scOracle Mysql Workbench+2 | 9/12/2019 | 17/6/2026 | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns. | |
| Modificada | Alta (7.5) | 8.0% | — | SqliteOracle Mysql WorkbenchSiemens Sinec Infrastructure Network ServicesApache Guacamole+2 | 9/12/2019 | 17/6/2026 | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. | |
| Modificada | Media (5.5) | 0.57% | — | SqliteNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityOracle Mysql Workbench+2 | 9/12/2019 | 17/6/2026 | alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements. | |
| Modificada | Crítica (9.8) | 4.3% | — | SqliteNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityOracle Mysql Workbench+1 | 5/12/2019 | 17/6/2026 | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. | |
| Modificada | Alta (7.2) | 0.81% | — | Inist Ezmaster | 29/11/2019 | 17/6/2026 | The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance (container) is launched with advanced capabilities (not launched as root) | |
| Modificada | Alta (8.8) | 3.1% | — | InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+3 | 25/11/2019 | 17/6/2026 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application. | |
| Modificada | Crítica (9.8) | 2.3% | — | Netapp Ontap Select Deploy Administration Utility | 21/11/2019 | 17/6/2026 | ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account. | |
| Modificada | Alta (7.2) | 1.3% | — | Netapp Ontap Select Deploy Administration Utility | 21/11/2019 | 17/6/2026 | All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges. | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Media (5.5) | 1.00% | — | Apache POIOracle Application Testing SuiteOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+23 | 23/10/2019 | 17/6/2026 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing. | |
| Modificada | Alta (8.1) | 3.8% | 💥 PoC | Libssh2Fedoraproject FedoraOpensuse LeapDebian Linux+6 | 21/10/2019 | 17/6/2026 | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service… |